Grassfeld's Information Security Policy
This Information Security Policy describes the relevant measures implemented by Grassfeld B.V. regarding information security from both a strategic and operational perspective. This policy is intended for users of the Grassfeld application and website.
Last updated on June 17,2026

Grassfeld takes information security seriously in order to safeguard the confidentiality, integrity, and availability of information. Grassfeld continuously evaluates and improves its security measures based on a risk-based approach and in line with generally accepted security principles.
External parties with whom Grassfeld collaborates, including financial institutions and security partners, are required to comply with the applicable laws, regulations, and security standards relevant to their sector.
1.
User Access Control
1.1
Registration and Authentication:
External users must register for access through a secure online process that verifies the identity of the user. Each user is authenticated using a combination of a password and multi-factor authentication (MFA).
1.2
Authorization:
Access is granted solely based on the tasks the user is required to perform within the system. Users are only granted access to functions and data relevant to their role.
1.3
Administrative Accounts:
Accounts with elevated privileges are used exclusively for performing administrative tasks. All unused or unnecessary user accounts and email addresses are removed or deactivated by the IT administrator.
User accounts are removed or deactivated immediately upon termination of employment, contract, or agreement by the IT administrator and documented accordingly.
Grassfeld does not permit the use of shared accounts as a general principle. In exceptional situations where shared accounts are unavoidable, additional security measures are implemented, including restricted access rights, activity logging, and periodic evaluations of account usage.
If employees had access to shared accounts, the credentials of those accounts are immediately changed by the IT administrator.
2.
Data Protection
2.1
Data Encryption:
Data stored within the Grassfeld platform and application is encrypted using current and widely recognized encryption standards. Stored data is protected using, among other things, AES-256 encryption, while data transmission is secured using TLS 1.2 or higher.
In addition, systems and data are continuously monitored for potential attacks and data breaches in order to immediately limit detected threats.
2.2
Data Classification:
All data processed and stored by Grassfeld is categorized by the security officer and reviewed periodically, at least annually.
Data is classified based on sensitivity and the potential impact on business operations in the event of unauthorized access or loss. Data is managed, protected, and secured in accordance with the sensitivity level of the relevant category.
2.3
Data Storage:
Data is stored in a multilayer secured database with strictly limited accessibility. Access is restricted to authorized personnel who comply with applicable authentication requirements.
When a user deletes their account, the associated data is destroyed in accordance with applicable retention periods and internal procedures. After deletion, the data can no longer be actively used or made accessible.
2.4
Backups and Recovery:
Grassfeld periodically creates secure backups of business-critical systems and data to ensure service continuity, availability, and recoverability.
Backups are encrypted and accessible only to authorized personnel. Recovery procedures are periodically tested to verify the reliability and availability of backups.
Backups of individual user data are retained only to the extent necessary for security, continuity, and legal obligations.
2.5
Data Sharing:
The sharing of personal and financial information within the application is subject to strict protocols and only occurs with the explicit consent of the user.
Grassfeld does not sell data to third parties.
Please refer to the Privacy and Cookie Policy for more information regarding the processing of personal data and the rights of data subjects.
3.
Employee Responsibilities
3.1
New Employees:
All new employees (both internal and external) are informed of this Information Security Policy and the obligations arising from it at the start of their engagement.
3.2
Compliance:
Employees are required to comply with the guidelines described in this policy. Violations of this policy may result in consequences in accordance with the applicable employment regulations.
3.3
Patch and Vulnerability Management:
Grassfeld assesses known vulnerabilities in software, infrastructure, and systems based on risk and urgency.
Critical security updates are prioritized and implemented accordingly. Systems that are no longer supported or cannot be adequately secured are replaced, isolated, or decommissioned.
4.
User Responsibilities
4.1
Protection of Access Credentials:
Users are responsible for maintaining the confidentiality of their passwords. Passwords may not be shared or written down.
If a password is suspected to be compromised, it must be changed immediately.
4.2
Device Security:
To ensure the secure use of the application, users must ensure that their devices are equipped with the latest security updates and appropriate antivirus software.
5.
Security by Design
5.1
Proactive Protection:
Grassfeld applies the principle of Security by Design. This means that security is structurally integrated into the architecture, development, and implementation of systems and processes from the earliest design stages.
Security measures are not added afterward but form an integral part of the development of products and services.
Grassfeld’s security partner receives information about threats and vulnerabilities from various sources, including internal and external information-sharing initiatives and both commercial and non-commercial parties.
5.2
Risk Minimization:
The design and implementation of the application follow the principle of least privilege, ensuring that users only have access to data and functionalities necessary for their role.
This limits potential damage in the event of a security incident or misuse.
Examples of implemented security measures include IP verification per user session, secure connections to proprietary servers, and account registration through email, password, and SMS verification.
5.3
Pseudonymization:
Users of Grassfeld are represented within the system by a pseudonymous identifier. This means that Grassfeld does not maintain a direct link between system data and the identity of a user.
This pseudonymous identifier is only accessible through a secure connection specifically designed for communication with the user.
Information added and stored by users is used solely to improve Grassfeld’s algorithms and services.
Please refer to the Privacy and Cookie Policy for more information regarding pseudonymization and the processing of personal data.
6.
Incident Management
6.1
Incident Response:
In the event of a security incident, Grassfeld follows a structured incident response procedure consisting of reporting, assessment, containment, investigation, recovery, and documentation.
Incidents are immediately escalated internally to the incident response team. Affected systems and network segments may be temporarily isolated to prevent further damage.
Forensic investigations are conducted to analyze the cause, impact, and scope of the incident. After recovery, appropriate measures are taken to prevent recurrence.
All relevant incidents are documented and evaluated.
If an incident affects users or business partners, Grassfeld will notify the relevant parties in accordance with applicable laws and regulations.
Grassfeld maintains a continuously available security team.
Please refer to the Privacy and Cookie Policy for the procedure regarding data breach notifications.
6.2
Responsible Disclosure:
Grassfeld encourages security researchers and users to responsibly report potential vulnerabilities.
Reports can be submitted via: security@grassfeld.com
Grassfeld requests reporters to:
- refrain from exploiting the vulnerability;
- refrain from copying, modifying, or deleting user data;
- treat the vulnerability confidentially until it has been resolved;
- provide sufficient information to reproduce the vulnerability.
Grassfeld treats all reports confidentially and will not initiate legal action against reporters acting in good faith and in accordance with the above conditions.
7.
Suppliers and Security Partners
7.1
External Parties:
Grassfeld collaborates with external suppliers and security partners for parts of its services and infrastructure.
When selecting suppliers, Grassfeld assesses, among other things, security measures, reliability, and compliance with relevant laws and regulations.
Appropriate contractual agreements regarding information security, confidentiality, and data protection are established with suppliers and reviewed periodically.
8.
Compliance and Legislation
8.1
Regulatory Compliance:
Grassfeld operates in accordance with the requirements of applicable data protection legislation.
Information regarding compliance with legal obligations is included in the Privacy and Cookie Policy.
9.
Policy Updates
9.1
Revisions:
This policy may be updated to reflect changes in legal, technical, or organizational developments.
Grassfeld advises users to review this policy regularly to stay informed about any changes.
Contact Details
For questions regarding this policy or to report security incidents, please contact:
Rodezand 80
3011 AN Rotterdam
The Netherlands
Grassfeld B.V.
security@grassfeld.com


